
AidWP – Donation & Payment Forms (Stripe Powered) Security & Risk Analysis
wordpress.org/plugins/wp-stripe-donationCreate fast donation and payment forms. Accept payments on WordPress with Stripe — no WooCommerce required.
Is AidWP – Donation & Payment Forms (Stripe Powered) Safe to Use in 2026?
Generally Safe
Score 99/100AidWP – Donation & Payment Forms (Stripe Powered) has a strong security track record. Known vulnerabilities have been patched promptly.
The "wp-stripe-donation" v3.3.0 plugin exhibits a mixed security posture. While it has no currently unpatched vulnerabilities, its static analysis reveals significant concerns. A substantial attack surface exists with 6 unprotected AJAX handlers, presenting a prime target for unauthorized actions. The presence of 11 dangerous functions, including the potent `unserialize`, and a high percentage of SQL queries not using prepared statements (68%) indicate potential for code injection and data manipulation vulnerabilities.
Taint analysis further highlights a critical risk with one flow identified as having unsanitized paths, which could lead to severe security breaches if exploited. Although the plugin includes nonce and capability checks, their absence on a majority of AJAX entry points is a major weakness. The vulnerability history, despite having no recent critical or high-severity issues, shows a pattern of missing authorization and CSRF vulnerabilities, suggesting a recurring tendency for insecure handling of user input and actions.
In conclusion, while the plugin has a clean record for unpatched CVEs, the static analysis and taint results point to significant underlying security flaws. The high number of unprotected AJAX handlers, the use of dangerous functions, and the prevalence of raw SQL queries are critical areas that need immediate attention. The historical pattern of authorization and CSRF issues reinforces the need for more robust security measures to prevent future exploitation.
Key Concerns
- Unprotected AJAX handlers
- Dangerous function usage (unserialize)
- Low prepared statement usage in SQL
- Taint flow with unsanitized paths (High severity)
- Bundled library Freemius v1.0 (potentially outdated)
- Low output escaping percentage
AidWP – Donation & Payment Forms (Stripe Powered) Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WordPress Stripe Donation and Payment Plugin <= 3.2.3 - Missing Authorization
Accept Stripe Donation – AidWP <= 3.1.5 - Cross Site Request Forgery
AidWP – Donation & Payment Forms (Stripe Powered) Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
AidWP – Donation & Payment Forms (Stripe Powered) Attack Surface
AJAX Handlers 6
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
AidWP – Donation & Payment Forms (Stripe Powered) Maintenance & Trust
Maintenance Signals
Community Trust
AidWP – Donation & Payment Forms (Stripe Powered) Alternatives
Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions
wp-full-stripe-free
🚀 Create Stripe payment forms for WordPress. Accept credit cards, Apple Pay, donations, subscriptions & more. Easy setup, no coding needed!
WPayme – Payment Forms & Gateways for WordPress
wpayme
Effortlessly create payment forms and accept payments anywhere on your WordPress site using simple shortcodes. WPayme lets you embed flexible forms on …
Kali Forms — Contact Form & Drag-and-Drop Builder
kali-forms
Build contact forms for your WordPress website in minutes through the Drag & Drop builder and Guided Emails for entries notifications.
Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More
better-payment
Better Payment allows you to automate payment transactions to manage payments, donations, subscriptions, sell products, etc on your Elementor website.
Paymattic – Secure, Simple Payment & Donation with Subscription Payments, Recurring Donations, Customer Management
wp-payment-form
Create payment form, donate button to accept payments and donations. Manage subscription payment, recurring donation with customer/donor management.
AidWP – Donation & Payment Forms (Stripe Powered) Developer Profile
13 plugins · 8K total installs
How We Detect AidWP – Donation & Payment Forms (Stripe Powered)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-stripe-donation/assets/css/wpsd-font-awesome/css/all.min.css/wp-content/plugins/wp-stripe-donation/assets/css/wpsd-admin.css/wp-content/plugins/wp-stripe-donation/assets/js/wpsd-admin.jshttps://cdn.jsdelivr.net/gh/linways/table-to-excel@v1.0.4/dist/tableToExcel.jswp-stripe-donation/assets/css/wpsd-font-awesome/css/all.min.css?ver=wp-stripe-donation/assets/css/wpsd-admin.css?ver=wp-stripe-donation/assets/js/wpsd-admin.js?ver=HTML / DOM Fingerprints
wpsd-admindata-wpsd-iddata-wpsd-placeholderdata-wpsd-colorwpsdAdminScript<div class="wpsd-donation-form-wrap"><form id="wpsd-donation-form-<div class="wpsd-progress-bar-wrapper"><div class="wpsd-progress-bar-inner" style="width: